Privacy Policy
Your privacy matters to us. We're committed to transparency and protecting your data.
Last updated: August 30, 2026
Up to dateOur Commitment
At bsynqed, we believe in “Your Data, Your Control.” We built this platform for independent property operators who value transparency and trust. We're committed to protecting your privacy and being transparent about how we collect, use, and protect your information.
This Privacy Policy explains our practices regarding data collection, usage, and your rights. We've written it in plain language because we believe you should understand what happens with your data.
Information We Collect
We collect information necessary to provide and improve our services:
- Account Information: Name, email address, phone number, and property details you provide during registration
- Property Data: Property information, room/bed configurations, rates, availability, and booking data
- Booking Data: Guest information, booking details, payment information (processed securely through Stripe)
- Usage Data: How you interact with our platform to help us improve the service
- Technical Data: IP address, browser type, device information for security and functionality
- Health Information: Where a property uses our wellness and spa features, guests may be asked for treatment-related health details before a booking (see below)
- Identity Documents: Where local law requires guest registration, staff may photograph a guest's passport or identity document (see below)
- Location Data: Only where a property enables location-based features such as geofenced staff clock-in, and only while the app is in use (see below)
- Crash and Diagnostic Data: Error reports that help us fix faults (see below)
How We Use Your Information
We use your information to:
- Provide and maintain our PMS and Channel Manager services
- Process bookings, payments, and manage your property operations
- Sync data with OTA partners (Booking.com, HostelWorld) as you configure
- Send you important service updates and notifications
- Improve our platform based on your usage and feedback
- Ensure security and prevent fraud
- Comply with legal obligations
We never sell your data. We don't share your information with third parties except as necessary to provide our services (e.g., OTA integrations you configure, payment processors) or as required by law.
Data Sharing
We share your data only when necessary:
- OTA Partners: When you connect Booking.com, HostelWorld, or other OTAs, we sync availability and booking data as configured
- Payment Processor: Stripe processes payments securely - we don't store full payment card details
- Service Providers: We may use trusted third-party services for hosting, email delivery, and analytics (all bound by confidentiality agreements)
- Error Monitoring: We use Sentry to receive crash and error reports from our apps, so we can find and fix faults. What is and is not included is described under Crash Reporting below
- Legal Requirements: If required by law or to protect our rights and safety
Health Information (Wellness and Spa)
Where a property uses our wellness, spa or thermal features, a guest may be asked to complete a short health questionnaire before a treatment. This can include allergies, current medications, heart conditions, recent injuries and pregnancy.
Why it is collected: a therapist needs to know about contraindications before performing a treatment. It is used for that purpose only. It is never used for marketing, never used to build a profile, and never sold.
Consent comes first. Health information is a special category of personal data under GDPR Article 9. The guest is shown a consent screen explaining what is being asked and why, and nothing is recorded unless they agree. Consent can be withdrawn at any time.
Who can see it: staff at the property delivering the treatment. It is not shared with OTA partners, payment processors, or any other third party.
Identity Documents and Guest Registration
Many countries legally require accommodation providers to record guest identity details on check-in. Where a property is subject to those rules, staff can photograph a guest's passport or identity document using the app.
Lawful basis: compliance with a legal obligation that applies to the property, or the property's legitimate interest in verifying who is staying. The property, not bsynqed, decides whether this is required and is the controller of that data.
How it is handled: the image is transmitted over an encrypted connection and stored against the booking. It is retained for as long as local registration law requires and then deleted. It is never used for any purpose beyond guest registration, and never shared with OTA partners or advertisers.
Location Data
Some optional features use device location: geofenced staff clock-in, which confirms a staff member is on-site when they start a shift, and tour meeting points.
- Only while you are using the app. We request when-in-use access only. We do not track location in the background, and the app does not run location services when it is closed.
- Only if the property enables it. If a property does not use geofenced clock-in, no location is collected at all.
- You can refuse. Location permission can be declined or revoked in your device settings at any time; the rest of the app continues to work.
Location is used to answer one question at one moment, such as whether a clock-in happened at the property. We do not build location histories or movement profiles.
Biometric Authentication
The app can be unlocked with Face ID, Touch ID or a fingerprint. This is handled entirely by your device's own secure hardware. Your fingerprint or face data never leaves your device, is never transmitted to us, and is never stored on our servers. The app only receives a yes or no answer from the operating system. You can use a password or PIN instead.
Crash Reporting and Diagnostics
When the app hits an error, it sends a report to Sentry, our error-monitoring provider, so we can find and fix the fault. A report includes the technical error, the device model and operating-system version, and a trail of the screens visited beforehand.
It is attached to a staff member's account. The signed-in user's id and email address are included, because support cannot act on an anonymous crash report.
What we deliberately do not send from the live app:
- No screenshots. Our apps can attach a screenshot to a crash report, and this is switched off in the live app, because the screen at the moment of a crash may show a guest's folio, an identity document or a health questionnaire.
- No device IP address. Also switched off in the live app.
Both remain enabled in our internal development and testing builds, which contain no real guest data. Crash reports are sampled rather than exhaustive, and are used only to diagnose faults.
Google User Data & Third-Party Calendar Connections
bsynqed lets you connect a third-party calendar (such as Google Calendar or Microsoft Outlook) so the Meetings feature can check your availability and keep your bookings in sync. When you connect a Google account, bsynqed accesses your Google data only to provide this feature.
What we access, and why:
- Free/busy times: so we know when you are already busy and guests cannot book you during those times (preventing double-bookings).
- Calendar events: to create, update, and remove events for meetings booked through bsynqed, and to show your existing events inside your bsynqed calendar.
How we protect it: the access you grant is stored as encrypted OAuth tokens (AES-256-GCM) and used only to operate the calendar features you enabled. You can disconnect your calendar at any time inside bsynqed, and revoke bsynqed's access from your Google Account permissions; once disconnected, we stop accessing your Google data.
Limited Use: bsynqed's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. We do not transfer Google user data to others except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition with your consent.
Your Rights
You have control over your data:
- Access: Request a copy of all data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data (subject to legal retention requirements)
- Data Portability: Export your data in a machine-readable format
- Objection: Object to certain types of data processing
- Withdrawal: Withdraw consent where processing is based on consent
To exercise these rights, contact us at [email protected]. We'll respond within 30 days.
Cookies and Tracking
We use cookies and similar technologies to:
- Keep you logged in and maintain your session
- Remember your preferences and settings
- Analyze how our platform is used to improve it
- Ensure security and prevent fraud
You can control cookies through your browser settings. Note that disabling cookies may affect some platform functionality.
Data Security
We implement industry-standard security measures:
- Encryption in transit (HTTPS/TLS) and at rest
- Secure authentication with two-factor authentication support
- Role-based access controls
- Regular security audits and updates
- Secure data backups
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Offline Data Storage
To provide a better user experience, our portal and booking engine may store limited data on your device when you use our services offline:
- Basic Booking Information: Encrypted booking status, dates, and property information (expires after 7 days)
- Product Catalog: Menu items and product information for offline browsing (no personal information)
- Draft Orders: Shopping cart items with customer first name only (expires after 24 hours, encrypted)
- UI Preferences: Theme, language, and display settings (no personal information)
What we do NOT store offline:
- Payment methods, card numbers, or CVV codes
- Full guest profiles or customer information (only first name in draft orders)
- Message drafts or unencrypted messages
- Full invoice details
- Authentication tokens (stored securely in httpOnly cookies only)
Security Measures:
- All sensitive offline data is encrypted using AES-256-GCM encryption
- Encryption keys are generated per session and stored only in sessionStorage (cleared when you close your browser)
- Encryption keys are never transmitted to our servers
- Automatic expiration and cleanup of stored data
- All offline data is securely deleted when you log out
You can clear all offline data at any time through your browser settings or by logging out of your account.
Data Retention
We retain your data for as long as your account is active or as needed to provide services. If you cancel your account, we retain data for 90 days to allow for account recovery, after which we delete it unless legal requirements mandate longer retention.
Children's Privacy
Our services are not intended for individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We'll notify you of significant changes by email or through our platform. The “Last updated” date at the top indicates when changes were made.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
- Email: [email protected]
- Address: 124 City Road, London, United Kingdom, EC1V 2NX